Security
This page summarizes the administrative, physical, and technical safeguards Ayureon, Inc. applies to protect Protected Health Information (PHI) and electronic PHI (ePHI) handled by the Ayuva® platform. It is grounded in the HIPAA Privacy Rule (45 CFR Part 160 and 164, Subparts A and E) and the HIPAA Security Rule (45 CFR Part 164, Subparts A and C). Ayureon, Inc. handles PHI as a HIPAA business associate on behalf of the healthcare organizations it serves, under written Business Associate Agreements.
Scope
This policy applies to all workforce members, contractors, subcontractors, and AI systems that create, receive, maintain, or transmit PHI on behalf of Ayureon, Inc.
Minimum Necessary Standard
Access to PHI is limited to the minimum necessary to accomplish the intended purpose:
- Role-based access controls define PHI access per role (clinical operations, engineering, AI systems).
- AI systems that access PHI operate under audit-logged, scoped permissions; agents that do not require PHI operate on de-identified or non-PHI data.
- Query-level enforcement ensures API requests scope PHI access to the specific patient and data elements needed.
Patient Rights
Patients hold their HIPAA rights — access, amendment, an accounting of certain disclosures, restrictions, confidential communications, and revocation of authorization — with their healthcare provider, as described in the provider's Notice of Privacy Practices. Ayureon, Inc. supports providers in fulfilling these requests within the regulatory timeframes:
- Right to Access: records made available to the provider promptly to support its 30-day response obligation.
- Right to Amend: amendments incorporated as directed by the provider.
- Right to Accounting of Disclosures: a 6-year disclosure log is retained (excluding TPO disclosures).
- Right to Request Restrictions: self-pay restriction requests honored per HITECH, as directed by the provider.
- Right to Revoke Authorization: prospective only.
Requests received directly by Ayureon, Inc. are forwarded to the relevant provider within five business days.
Uses and Disclosures
Ayureon, Inc. uses and discloses PHI only as permitted by its Business Associate Agreements and applicable law:
- To provide contracted services: scheduling, consent capture, clinical data exchange, care-coordination workflows via FHIR and connected networks.
- As directed by the provider: transmission to treating providers and public-health registries.
- As required by law: including required disclosures to the individual (via the provider) and to the HHS Office for Civil Rights for compliance investigations.
Sale of PHI is prohibited. PHI is not used for marketing. De-identification is performed only in accordance with 45 CFR 164.514 and applicable agreements.
Administrative Safeguards
- Risk Analysis: comprehensive risk analysis annually and upon significant system changes.
- Risk Management Plan: documented measures to reduce identified risks.
- Sanctions Policy: disciplinary action up to termination for workforce policy violations.
- Information System Activity Review: regular review of audit logs, access reports, and security incident tracking.
- Workforce Training: HIPAA training for all workforce members with production access; new personnel trained within 30 days of onboarding.
- Contingency Plan: data backup, disaster recovery, and emergency-mode operations procedures.
Technical Safeguards
- Access Controls: unique user identification, passwordless-first authentication for staff consoles, automatic logoff, and encryption.
- Audit Controls: ePHI access recorded and examined; audit logging is enforced at the code level and logs are retained per HIPAA requirements.
- Integrity Controls: mechanisms to authenticate ePHI and protect against improper alteration or destruction, including cryptographic integrity records for signed consents.
- Transmission Security: TLS 1.2+ for all data in transit; time-limited, scoped URLs for document access.
Physical Safeguards
The Ayuva® platform, operated by Ayureon, Inc., runs on secured cloud infrastructure in the United States:
- Facility controls are provided by our cloud infrastructure provider's certified data centers.
- Workstation Security: screen-lock policies and prohibition on PHI display in public areas.
- Device and Media Controls: encryption at rest (AES-256) for databases and object storage; secure disposal procedures for any hardware containing ePHI.
Subcontractor (Business Associate) Management
- Ayureon, Inc. maintains a current inventory of subcontractors that handle PHI.
- Written agreements, including Business Associate Agreements, are required before any subcontractor accesses PHI.
- Subcontractor compliance is reviewed annually.
- Non-compliant subcontractors are notified and given a defined cure period before termination.
Breach Response
As a business associate, Ayureon, Inc. notifies the affected healthcare organization of any breach of unsecured PHI without unreasonable delay — targeting 24–48 hours and in no event later than the regulatory deadline (45 CFR 164.410) — with the information the organization needs to meet its own notification obligations to individuals, HHS, and state regulators. Detailed procedures are maintained in our Incident Response & Breach Notification Plan.
Reporting a Security Concern
If you believe you have discovered a security vulnerability or PHI exposure related to an Ayureon, Inc. service, contact security@ayureon.com. Responsible disclosure is appreciated; please do not access data beyond what is necessary to demonstrate the issue.
Policy Review
This policy is reviewed annually or upon significant regulatory or operational changes.